Microsoft has pushed out the August 2026 Patch Tuesday update for Windows 10, delivering the cumulative security package known as KB5120249. This release is critical for organizations and users still relying on Windows 10 under the Extended Security Updates (ESU) program, which keeps the operating system protected until October 2027.
The update is officially listed as the 2026-08 Cumulative Update for Windows 10 Version 22H2 for x64-based Systems (KB5120249). It addresses more than 400 security vulnerabilities, ensuring that legacy systems remain secure against emerging threats. While the update installs in under five minutes, it arrives alongside several other bundled changes, including a new Recovery Environment update and .NET Framework patches.
What’s New in Windows 10 KB5120249?
For everyday users, the most noticeable change is the version bump. After installing KB5120249, your system will be running Build 19045.7548. If you are on Windows 10 Enterprise LTSC 2021, the build moves to 19044.7548. These builds share the same underlying platform release, though LTSC users will notice a cleaner experience due to the absence of consumer-focused bloat.

Despite the extensive list of security fixes, there are no major visual or UX changes in this update. Windows 10 is in maintenance mode, meaning new features are no longer being added. However, Microsoft has quietly begun rolling out the new OneDrive Photos app to Windows 10 PCs via the OneDrive sync client. This is unrelated to KB5120249 and should not be expected as part of the patch.
Key Changes: Secure Boot and Backup Fixes
Two specific areas see notable improvements in this month’s release. First, Microsoft is expanding the range of PCs eligible for Secure Boot certificate updates. By adding more devices to its high-confidence range, the company ensures that more Windows 10 systems can maintain the security standards required for modern computing.
Second, the update resolves a bug affecting File History automatic backups for enterprise customers using Server Message Block (SMB). Previously, users encountered invalid credentials errors that prevented scheduled backups from running. Microsoft confirmed in the release notes that KB5120249 resolves this issue, restoring functionality for critical data protection workflows.
For those monitoring system security, the Secure Boot status can be verified in the Windows Security app under Device Security. Most users should see a green checkmark indicating the status is fully updated. Older hardware may display a yellow warning if firmware limitations prevent certificate application, while a red alert indicates action is required.
Download and Installation
Microsoft provides KB5120249 through multiple channels. The primary method remains Windows Update, which is recommended for most users due to its efficiency and smaller download size, often under 500MB.
For those who prefer offline installation or are managing systems where Windows Update is unreliable, Microsoft has posted direct download links for the .msu offline installer on the Update Catalog. These are available for both 64-bit and ARM-64 architectures.

To install via Windows Update, navigate to Settings > Update & Security > Windows Update and click Check for updates. If you choose the offline installer, ensure your system is enrolled in the ESU program, as the update requires this subscription to install successfully.
What This Means for You
If you are still running Windows 10, installing KB5120249 is essential. It closes hundreds of security gaps and ensures your system remains compliant with current security standards. The Secure Boot updates are particularly important for maintaining the integrity of your boot process, which is a prerequisite for running modern security software and potentially upgrading to Windows 11 in the future.
Enterprise administrators should verify that File History backups are functioning correctly after installation, especially on systems using SMB for storage. The resolution of the credentials error should restore automated backup schedules without manual intervention.

While Windows 10 is approaching the end of its lifecycle, the ESU program provides a vital bridge. By keeping your systems updated with patches like KB5120249, you can continue to operate securely while planning your transition to a supported operating system. Microsoft’s commitment to addressing security issues through Patch Tuesday demonstrates that legacy support remains a priority for enterprise stability.
Source: Windows Latest
Build details:
- Build 19044.7548
- Build 19045.7663
- KB5121003
- kb5121003
Over to you: Are you planning to stick with Windows 10 under ESU, or is it time to upgrade to Windows 11?



